DefectDojo is an association between open source application vulnerabilities and security applications.
It allows you to manage your application security program, keep the information productof and apps, scan schedules, discover vulnerable access points and forward your findings to security scanners.
While traceability and metrics are the ultimate goal, DefectDojo is a debugger at its core. The program allows traceability between multiple projects and test cycles and allows detailed reporting.
How does DefectDojo work?
DefectDojo is based on a model that allows absolute flexibility in testing needs.
- DefectDojo starts with a product type.
- Each product type can have one or more products.
- Each product may have one or more commitments.
- Each commitment can have a test.
- Each Test may have one or more findings
Installation
$ git clone https://github.com/DefectDojo/django-DefectDojo $ cd django-DefectDojo $ ./setup.bash $ ./run_dojo.bash
Application snapshots
You will find a user guide for the program here.